Frequently Asked Questions.
Everything you need to know about in-place file encryption mechanics, crash resilience, password security guarantees, and zero-telemetry privacy — organized systematically from beginner fundamentals to deep cryptographic engineering.
Beginner & Fundamentals
Essential concepts, installation basics, offline principles, and getting started.
What is Universal Vault and what makes it unique?↓
Universal Vault is an ultra-lightweight (<3 MB), sovereign authenticated encryption suite (AEAD) engineered for fast, authenticated protection of files and recursive directories across Windows, Linux, macOS, and Android. Statically compiled with zero runtime dependencies (no Python, no Node.js, no C++ redistributables, and no administrator privileges required), it completely eliminates the bloated container files and temporary folder disk leaks of legacy tools by streaming 100% in-place directly on disk.
How do I lock and unlock files and folders using the CLI terminal?↓
Once installed, the global `vault` command is available from any terminal or PowerShell window across your system: • To Lock a File: Run `vault lock "Confidential.pdf"`. You will be prompted to enter your master password silently with zero shoulder surfing. • To Lock a Directory Recursively: Run `vault lock "/data/projects/secret_repo"` or `vault lock .` to lock the current working directory. • Scripting / CI Automation: Pass an inline password via `vault lock "backup.tar" -p "MyMasterPassword123"`. • To Unlock: Run `vault unlock "Confidential.pdf"` (or `vault unlock "/data/projects/secret_repo"`). Universal Vault validates the master HMAC anti-tamper tag, reverts the ciphertext in-place, and restores your 100% original unencrypted files bit-for-bit. • To Inspect: Run `vault status .` to non-destructively inspect encryption states.
What are the portable (zero-install) options for locking and unlocking files?↓
If you prefer a zero-footprint workflow without modifying system PATH settings: • Portable CLI Binaries: Drop `vault.exe` (Windows), `vault_linux_amd64` (Linux), or `vault_darwin_arm64` (macOS) onto a USB drive and execute `./vault lock <path>` directly. • 1-Click Launchers (Windows): Double-click `Lock.bat` to encrypt in-place, `Unlock.bat` to decrypt and verify integrity, or `Status.bat` to inspect lock state. • Portable Shell Scripts (Linux & macOS): Run `./lock.sh /path/to/files`, `./unlock.sh`, or `./status.sh`. • Offline Browser WebApp (`Vault_App.html`): Open the standalone HTML file in any browser (Chrome, Brave, Safari, Edge, Firefox). Encrypt, decrypt, and stream 4K videos directly in volatile RAM with zero disk writes. • Android Native App: Install `UniversalVault-v5.5.2.apk` for 100% in-place SAF streaming with hardware write barriers (`Os.fsync`).
Is Universal Vault free, and are there any subscription fees or limits?↓
Universal Vault is 100% free and open-source under the permissive MIT License. There are zero subscription tiers, zero in-app purchases, zero premium locks, zero telemetry, and zero feature paywalls. You can use it freely for personal, commercial, academic, and enterprise workloads.
Do I need an internet connection or user account to use Universal Vault?↓
No. Universal Vault is an entirely air-gapped, sovereign cryptographic tool. You never create an account, register an email, or connect to a remote server. The binary contains zero networking libraries or telemetry trackers, executing all computations 100% locally within your device silicon.
Where does Universal Vault store my encrypted files?↓
Universal Vault does not upload files to remote servers or cloud drives. Files remain exactly where they sit on your local SSD, hard drive, USB flash drive, or Android storage.
Operations & Practical Workflows
In-place streaming mechanics, folder recursion, status inspection, and performance benchmarks.
What does "in-place" file encryption mean, and why is it superior to 7-Zip or WinRAR?↓
Conventional archivers like 7-Zip or WinRAR create a duplicate copy of your file in an operating system temporary directory (such as %TEMP% or /tmp) before creating an archive, requiring 100% extra disk space and leaving unencrypted data in unallocated sectors. Universal Vault uses in-place streaming to modify bytes directly within existing physical disk blocks, requiring 0% extra storage overhead (0 KB temporary disk space) and eliminating forensic plaintext remnants.
Can I encrypt entire folders and directory structures?↓
Yes! Universal Vault natively locks entire directory trees recursively in-place. You do not need to create intermediate .zip or .tar archives. Simply run `vault lock "/data/projects/secret_repo"` or `vault lock .`, and the engine traverses and locks every file inside directly on disk with zero temporary container duplication. To restore, run `vault unlock "/data/projects/secret_repo"`.
Does locking a file rename it or append a .vault or .enc extension?↓
No. Universal Vault operates strictly in-place on the target file itself without renaming it or appending arbitrary extensions. A file named `Financial_Report.xlsx` retains its exact name while its byte contents on disk are transformed into authenticated AEAD ciphertext followed by the 104-byte recovery footer. You can verify lock state at any time using `vault status <path>`.
How do I check which files are locked or unlocked with `vault status`?↓
Run `vault status .` or `vault status <path>`. Universal Vault non-destructively inspects target files without modifying them and outputs a concise status summary: [LOCKED] Financial_Report.xlsx (locked (V5 Authenticated AEAD (100% Full-File))) [LOCKED] Backup_Archive.zip (locked (V5 Authenticated AEAD (100% Full-File))) [UNLOCKED] Notes.txt Status Summary: 2 Locked | 1 Unlocked If an operation was previously interrupted by a power failure, `vault status` also reports the interrupted state and exact byte offset.
Can I lock a file on Windows and unlock it on Android, Mac, or Linux?↓
Yes, 100% cross-platform bit interoperability is guaranteed. The VAULTV05 binary specification uses strict Big-Endian byte ordering and deterministic offsets. A file locked on a Windows PC can be seamlessly unlocked on macOS, Linux, Android (using our native Kotlin SAF app), or through our WebCrypto browser application.
What happens if I forget my password? Can customer support recover it?↓
There are strictly zero backdoors, master recovery keys, or escrow bypasses. Universal Vault enforces absolute mathematical zero-knowledge privacy. If you lose your password, the ciphertext cannot be decrypted by anyone, including the software authors. We strongly recommend storing master passphrases in a reputable password manager or offline safe.
How fast is Universal Vault, and what does the live progress bar show?↓
Because Universal Vault streams in 64 KB blocks and leverages hardware-accelerated AES-NI CPU instructions, throughput is bounded only by your drive's raw storage speed. On modern NVMe SSDs, throughput typically exceeds 450 MB/s to 1.2 GB/s with < 4.2 MB RAM consumption. The multi-phase live progress bar clearly reports current phase (`Key Deriv`, `Verifying`, `Decrypting`, `Encrypting`), processed megabytes, live transfer speed, and an accurate countdown ETA.
Cryptography & Architecture
Cipher selection, key derivation standards, MAC authentication, and endianness.
Why does Universal Vault use AES-256-CTR instead of AES-GCM or AES-CBC?↓
While AES-GCM is popular for network packets, it requires buffering authentication tags over entire message frames and forbids random byte-level writes. AES-CBC requires sequential ciphertext block chaining and is vulnerable to padding oracle attacks. AES-256-CTR operates as a true symmetric stream cipher where counter offsets can be calculated instantaneously as (byte_offset / 16). This allows arbitrary-offset block resumption and zero-overhead in-place transmutation without padding, while anti-tampering is handled by an independent Encrypt-then-MAC (EtM) envelope.
Why does Universal Vault use 600,000 PBKDF2-HMAC-SHA256 iterations?↓
600,000 rounds of PBKDF2-HMAC-SHA256 adheres strictly to the OWASP Gold Standard guidelines for password key derivation. It combines each passphrase with 32 cryptographically secure random salt bytes from the operating system entropy pool (/dev/urandom or Windows CryptGenRandom), imposing an insurmountable computational cost against GPU farm cracking and precomputed rainbow tables.
How does the Encrypt-then-MAC (EtM) signature protect against bit-flipping attacks?↓
In stream ciphers like CTR mode, flipping a bit in the ciphertext flips the corresponding bit in the decrypted plaintext. Universal Vault prevents this attack by implementing ISO/IEC 18033-4 Encrypt-then-MAC (EtM). A 32-byte HMAC-SHA256 authentication tag is computed across the complete encrypted payload. During unlock, the MAC is verified in constant time before any plaintext is released. If even a single bit has been altered or corrupted, execution halts instantly.
How does Universal Vault handle Little-Endian vs Big-Endian processor architectures?↓
All numeric header and footer fields (such as magic bytes, iteration counts, payload lengths, and resume offsets) are explicitly encoded using Network Byte Order (Big-Endian) via Go's encoding/binary.BigEndian and Java's ByteBuffer.order(ByteOrder.BIG_ENDIAN). This ensures seamless cross-architecture operation between x86_64, ARM64, and RISC-V platforms.
Hardware Fault Tolerance & Forensics
Power-cut resilience, 2-way crash recovery, POSIX write barriers, binary footers, and forensics.
What happens if my PC loses power or crashes halfway through an operation? How does Crash Recovery work?↓
Universal Vault provides deterministic, crash-safe fault tolerance backed by a 104-byte resumable footer and OS write barriers (`FlushFileBuffers` on Windows, `fsync` on POSIX/Linux/macOS, and `Os.fsync` on Android) committed on every 1 MB boundary. • If Interrupted While LOCKING: 1. To finish encryption: Run `vault lock <path>` — It automatically detects the checkpoint and resumes encrypting forward from the exact byte where it was stopped. 2. To cancel and recover the original file: Run `vault unlock <path>` — It cleanly rolls back the partially locked portion and restores your 100% original unencrypted file bit-for-bit! • If Interrupted While UNLOCKING: Run `vault unlock <path>` — It automatically resumes decrypting forward from the last safe checkpoint. • To Check Interrupted Progress: Run `vault status <path>` — It inspects and reports the interrupted state and exact byte offset.
Why does in-place encryption provide stronger anti-forensic security than traditional utilities?↓
Traditional utilities leave residual data because standard OS file deletion merely removes filesystem metadata pointers while unallocated flash sectors retain plaintext data until garbage collected or overwritten. By performing in-place streaming, Universal Vault overwrites plaintext sectors directly with ciphertext blocks, ensuring no plaintext fragments linger in swap partitions, temp caches, or SSD over-provisioning space.
Can quantum computers or supercomputers decrypt a Universal Vault container?↓
No. Brute-forcing a 256-bit symmetric key requires testing up to 2^256 combinations. Even if all the supercomputers on Earth combined forces, searching this keyspace would take billions of times the estimated lifespan of the universe. Against theoretical quantum computers utilizing Grover's Search Algorithm, AES-256 maintains a post-quantum security margin of 128 bits, which remains mathematically impregnable.
How does the Android app stream in-place without copying files through the Storage Access Framework (SAF)?↓
Universal Vault for Android uses Android's Storage Access Framework (SAF) via ContentResolver.openFileDescriptor(uri, "rw"). It streams raw bytes directly through the underlying Linux kernel file descriptor via FileChannel.map and streaming NIO buffers with hardware write barriers (`Os.fsync`), executing in-place writes without copying the file into internal app cache or private application storage.
No matching questions found.
Try another search term or click "All" to view every tier.
Sponsor Universal Vault or Feature Your Developer Tool
Reach security researchers, DevOps engineers, and privacy-conscious developers worldwide.
Your Files Belong to You.
Keep Them That Way.
Zero setup. Zero accounts. Zero telemetry. Download the binary, run a single command, and lock your files with mathematical certainty.
